Bug 60865 - Critical Update for security/clamav-devel
Summary: Critical Update for security/clamav-devel
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: freebsd-ports-bugs (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-01-03 17:00 UTC by rob
Modified: 2004-01-05 03:56 UTC (History)
0 users

See Also:


Attachments
clamav-devel.patch (1.03 KB, patch)
2004-01-03 17:00 UTC, rob
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description rob 2004-01-03 17:00:33 UTC
Critical Update for security/clamav-devel
Mote that the distfiles 'hack' is very temporary, and will be removed 
in the next update.

(E-mail from the dev-list):
----------------------------------------------------------------------
Dear Users,

all ClamAV snapshots newer than clamav-20031201 contain a bug that
completely disables detection of polymorphic viruses (Hybris, Magistr)
and other malware with multipart signatures. Please update to the latest
version and make sure the changelog contains the following entry:

* libclamav: fixed handling of multipart signatures (broken since
	     Dec 2). The bug was introduced by _me_ and not by the
             Thomas Lamy's patch. Problem found and reported by René
             Bellora <rbellora*tecnoaccion.com.ar>, Jean-Christophe
             Heger <jcheger*acytec.com> and Tomasz Papszun
             <tomek*clamav.net>.  Many thanks !

ClamAV 0.65 is NOT affected by this problem.

Best regards,
Tomasz Kojm
------------------------------------------------------------------------
Comment 1 Pete Fritchman freebsd_committer freebsd_triage 2004-01-05 03:56:27 UTC
State Changed
From-To: open->closed

Committed, thanks.  I kept using DISTNAME (no reason to switch to 
DISTFILES unless multiple files are involved), and added the WRKSRC 
line after the DEPENDS section.